What is DORA?
The Digital Operational Resilience Act (DORA), formally EU Regulation 2022/2554, is a European Union regulation establishing a unified framework for digital operational resilience across the EU financial services sector. DORA became applicable on 17 January 2025 following a two-year transition period. The regulation aims to ensure that financial entities operating in the EU can withstand, respond to, and recover from information and communication technology disruptions and threats.
DORA is structured around five core pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing. Together these pillars create a comprehensive operational resilience framework that affected entities must implement, maintain, and demonstrate to competent authorities.
DORA is enforced by national competent authorities including the FCA, the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA). Non-compliance carries administrative penalties, regulatory enforcement, and reputational consequences for affected financial entities and their critical ICT providers.
DORA operates as lex specialis to the NIS 2 Directive for financial entities. Where DORA addresses ICT risk management, incident reporting, operational resilience testing, information sharing, and ICT third-party risk, DORA provisions apply instead of equivalent NIS 2 provisions. Member States do not apply NIS 2 cybersecurity risk-management and reporting obligations to financial entities covered by DORA.
Specific DORA articles your organisation must address
- Article 6 to 16: ICT risk management framework requirements
- Article 17 to 23: ICT-related incident reporting timelines and classification
- Article 24 to 27: Digital operational resilience testing including Threat-Led Penetration Testing (TLPT) for significant financial entities
- Article 28 to 30: ICT third-party risk management including contractual provisions and subcontracting controls
- Article 41: Critical ICT third-party service provider oversight framework
- Article 45: Voluntary information and intelligence sharing arrangements
